CVE-2026-3981: itsourcecode Online Doctor Appointment System doctor_action.php sql injection
A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctoraction.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3981?
CVE-2026-3981 has a high severity due to the potential for SQL injection vulnerabilities that can lead to data breaches.
How do I fix CVE-2026-3981?
To fix CVE-2026-3981, validate and sanitize all user inputs, and use prepared statements for all database queries in the affected file /admin/doctor_action.php.
Which version of Online Doctor Appointment System is affected by CVE-2026-3981?
CVE-2026-3981 affects version 1.0 of the itsourcecode Online Doctor Appointment System.
What type of vulnerability is CVE-2026-3981?
CVE-2026-3981 is classified as an SQL injection vulnerability.
What file is associated with CVE-2026-3981?
CVE-2026-3981 is associated with the file /admin/doctor_action.php in the itsourcecode Online Doctor Appointment System.